Bug 238911

Summary: www/py-django22: Update to 2.2.3 (bugfix & security release)
Product: Ports & Packages Reporter: Kubilay Kocak <koobs>
Component: Individual Port(s)Assignee: Wen Heping <wen>
Status: Closed FIXED    
Severity: Affects Many People CC: ports-secteam, w.schwarzenfeld, wen
Priority: Normal Keywords: security
Version: LatestFlags: bugzilla: maintainer-feedback? (python)
koobs: merge-quarterly+
Hardware: Any   
OS: Any   
URL: https://docs.djangoproject.com/en/2.2/releases/2.2.3/
See Also: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=238910

Description Kubilay Kocak freebsd_committer freebsd_triage 2019-07-01 09:59:22 UTC
2.2.3 fixes:

CVE-2019-12781: Incorrect HTTP detection with reverse-proxy connecting via HTTPS¶

And two regressions in 2.2/2.2.1
Comment 1 Walter Schwarzenfeld 2019-07-01 14:13:30 UTC
See ports r505572.
Comment 2 Wen Heping freebsd_committer freebsd_triage 2019-07-01 14:15:57 UTC
Sorry I committed the update without noticing your PR.

wen
Comment 3 Kubilay Kocak freebsd_committer freebsd_triage 2019-07-01 14:19:26 UTC
That's OK, please reference the PR's when committing the VuXML entries
Comment 4 commit-hook freebsd_committer freebsd_triage 2019-07-01 14:39:45 UTC
A commit references this bug:

Author: wen
Date: Mon Jul  1 14:39:36 UTC 2019
New revision: 505575
URL: https://svnweb.freebsd.org/changeset/ports/505575

Log:
  - Document Django vulnerabilities.

  PR:		238911, 238910
  Submitted by:	koobs@

Changes:
  head/security/vuxml/vuln.xml